Ragnar Locker is a Windows ransomware family first observed in late 2019 and used in human-operated attacks against enterprise networks. Its operators employ double extortion, stealing sensitive information before encrypting systems and threatening to publish the stolen data unless a ransom is paid. Victims have included organizations in manufacturing, energy, financial services, government, information technology, and gaming, including Energias de Portugal and Capcom. The operators have also used DDoS attacks to increase pressure on victims and cooperated with Maze by publishing victim data through Maze’s leak platform.
The ransomware encrypts files on local volumes and mapped network drives, with observed deployments also exposing removable drives to encryption. Analyzed variants use Salsa20 for file encryption and RSA to protect encryption keys. Executables and ransom notes can be customized for individual victims. Ragnar Locker gathers host information, enumerates drives and services, and terminates selected database, backup, security, and remote-management software to unlock files and impede intervention. It specifically targets tools commonly used by managed service providers, including ConnectWise and Kaseya. It deletes volume shadow copies, disables Windows recovery features, and excludes selected system files and directories to preserve operating-system functionality. Language checks cause it to terminate on systems configured with certain former Soviet-region languages, while packing and anti-debugging mechanisms hinder analysis.
A distinctive deployment technique runs the ransomware inside an Oracle VirtualBox virtual machine containing a stripped-down Windows XP guest. Writable shared folders expose host disks and network drives to the guest, allowing encryption activity to appear on the host as legitimate virtualization activity and reducing visibility for host-based security tools. Operators have distributed unsigned Windows Installer packages through Group Policy after obtaining domain administrator access, using PowerShell and Group Policy for lateral deployment. Observed initial-access routes include attacks against Windows Remote Desktop Protocol connections and managed service provider environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To elevate privileges, the attacker exploits the CVE-2017-0213 vulnerability in the Windows COM Aggregate Marshaler to run arbitrary code with elevated privileges. | Analysis of Ragnar Locker Ransomware. First discovered in April 2020. Uses the increasingly popular “double extortion” tactic, in which the attacker first exfiltrates sensitive data, then triggers the encryption attack, threatening to leak the stolen data if the target refuses to pay the ransom.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed with medium confidence that IAB (Broker1) sold access to Sierra Packaging & Converting, and later the organization was compromised by Ragnar_Locker ransomware group.
The organization in question came to Sophos Rapid Response after falling victim to a Ragnar Locker attack in early 2020.
The Russian-speaking cybercriminal group has a dark web site under a different name, dubbed "Dunghill Leak," and doesn't have its own ransomware; Dark Angels has used variants of other ransomware such as Ragnar Locker.
Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining administrator-level access... they have used native Windows administrative tools such as Powershell and Windows Group Policy Objects (GPOs) to move laterally across the network.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
In past attacks, the Ragnar Locker group has used exploits of managed service providers or attacks on Windows Remote Desktop Protocol (RDP) connections to gain a foothold on targeted networks.
ntdll.dllのDbgUiRemoteBreakinの先頭5バイトを自身のオリジナルのフック関数へジャンプするようにメモリを書き換えます。
The Ragnar Locker actors used a GPO task to execute Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package.
暗号化ファイルの拡張子変更は、以下のようにMoveFileExを使用し、ファイル移動させることでリネームします。
ntdll.dllのDbgUiRemoteBreakinの先頭5バイトを自身のオリジナルのフック関数へジャンプするようにメモリを書き換えます。
Microsoft Installer (msiexec.exe) executes MSI package... [the GPO task] execute[s] Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package.
Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine to hide the ransomware from view.
Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine to hide the ransomware from view.
The ransomware in the guest environment can now fully access the host’s local disks, mapped network and removable drives... the ransomware encrypts the files on all available mapped network drives.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed within a VirtualBox-hosted Windows XP guest VM to evade host-based security controls. It maps the physical host's local, removable, and network drives into the guest, terminates selected processes and services, deletes volume shadow copies, encrypts accessible files, and drops a victim-specific ransom note. Operators also exfiltrate data before encryption to support extortion.
Ransomware that deploys a full virtual machine on targeted devices to evade security tools.
Ransomware noted for deploying a VirtualBox VM to hide malicious processes from scanners and avoid AMSI-related visibility.
Ransomware used in a prior attack against the victim organization, manually deployed across hundreds of computers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.